The G7 Cybersecurity Working Group released a call to action on September 3, urging governments and organizations across Canada, France, Germany, Italy, Japan, the U.K. and the U.S. to begin migrating away from cryptography that quantum computers could eventually break, a warning that lands squarely on an industry built around Bitcoin’s and Ethereum’s public-key systems.
The group warned that the precise arrival date of a cryptographically relevant quantum computer remains uncertain, but technological advances justify beginning preparations now.
Why the G7 warning matters for crypto
The central issue is not that quantum computers are about to drain Bitcoin wallets tomorrow. Current quantum machines cannot perform that attack.
Instead, the G7 crypto report highlights a migration problem that could take years to solve. Blockchains are not ordinary software applications that can simply receive a routine security patch. Changes to cryptographic primitives can affect consensus rules, wallet software, exchanges, custodians, hardware, applications and billions of dollars in existing assets.
The G7’s recommendations include raising awareness, developing national strategies, supporting research, strengthening public-private cooperation and incorporating post-quantum security into cybersecurity requirements and procurement. It also advocates a phased, risk-based migration that begins with identifying cryptographic assets and critical dependencies.
NIST has made a similar argument. The agency says organizations should migrate before quantum computers put current encryption at risk, noting that replacing cryptographic infrastructure can take many years.
Dustin Moody, a NIST mathematician and leader of its post-quantum cryptography standardization project, has described the industry as moving into a new phase. “We’re really moving from a research phase into a deployment phase,” Moody said in a 2026 interview.
That shift is particularly important for crypto because blockchain data is designed to remain available for extremely long periods.
Europe is already working against the clock
The G7 crypto report arrives as governments are increasingly putting concrete timelines behind their post-quantum plans.
The European Union adopted its Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography in June 2025. Under the roadmap, EU member states are expected to begin transitioning to post-quantum cryptography by the end of 2026, while high-risk use cases should be protected as soon as possible and no later than the end of 2030.
Those deadlines could eventually influence companies operating in digital assets, particularly institutional custodians, exchanges and infrastructure providers serving regulated markets.
The broader challenge is that post-quantum algorithms generally require different computational and storage characteristics from the compact cryptographic systems used today.
NIST’s finalized ML-DSA standard, for example, provides a post-quantum digital-signature framework designed to withstand attacks from large-scale quantum computers.
For blockchain networks, adopting such systems could mean larger signatures, additional bandwidth, greater storage requirements and potentially higher transaction costs. The result is a difficult balancing act between security and network efficiency.
Bitcoin and Ethereum are taking different approaches
Bitcoin developers have already begun exploring potential defenses. BIP-360, currently a draft proposal, introduces Pay-to-Merkle-Root, or P2MR, which removes Taproot’s vulnerable key-path spending mechanism and is designed to provide a quantum-resistant path for script-tree outputs.
Importantly, BIP-360 is not activated on Bitcoin, meaning it should not be interpreted as an implemented network-wide quantum solution.
A separate draft, BIP-361, focuses specifically on post-quantum migration and the eventual retirement of legacy signatures. Its existence underscores the growing recognition among Bitcoin developers that the issue involves more than simply creating a new signature algorithm.
Ethereum is pursuing a broader strategy. The Ethereum Foundation says its roadmap targets full post-quantum protection around 2029 and identifies several cryptographic areas requiring upgrades, including ECDSA account signatures and BLS validator signatures.
Ethereum researcher Justin Drake has framed the transition as more than a defensive exercise, calling post-quantum security “an opportunity” for Ethereum to distinguish itself as a future-ready financial system.
The real crypto risk may be the migration itself
The G7 crypto report ultimately reinforces a point that is becoming harder for the digital-asset industry to ignore: quantum preparedness is a governance problem as much as a cryptography problem.
Google Quantum AI researchers recently estimated that breaking the 256-bit elliptic-curve cryptography underlying systems such as Bitcoin’s secp256k1 could require substantially fewer quantum resources than previously estimated. Their study puts the attack within the range of future cryptographically relevant quantum computers, although no such machine exists today.
Google has separately set a 2029 target for migrating its own authentication systems to post-quantum cryptography, citing progress in quantum hardware, error correction and resource estimates.
That does not mean Bitcoin will be broken in 2029. It means the industry’s preparation window could be considerably shorter than a technology built around permanent, decentralized infrastructure would prefer.
The G7 crypto report therefore lands at a critical moment. Crypto developers must consider how to upgrade networks, move vulnerable assets, deal with dormant wallets and reach consensus without triggering disruption.
There is also the “harvest now, decrypt later” problem. Attackers can collect encrypted information today and potentially decrypt it once sufficiently powerful quantum computers become available. NIST considers this one of the reasons organizations cannot simply wait until quantum computers arrive before beginning migration.
For crypto, where transaction histories and public keys can remain visible indefinitely, the implications are particularly significant.
The G7 crypto report does not predict an imminent Bitcoin collapse. Instead, it delivers a more consequential warning for an industry built around long-lived infrastructure: waiting for Q-Day before starting the migration could be waiting too long.